ShuckwormÍÅ»ïͨ¹ýUSB·Ö·¢Æä×Ô½ç˵ºóÃÅPterodo

Ðû²¼Ê±¼ä 2023-06-20

1¡¢ShuckwormÍÅ»ïͨ¹ýUSB·Ö·¢Æä×Ô½ç˵ºóÃÅPterodo


6ÔÂ15ÈÕ£¬SymantecÅû¶Á˶íÂÞ˹Ïà¹ØºÚ¿ÍÍÅ»ïShuckworm¸üÐµĹ¤¾ß¼¯ºÍѬȾ¼ÆÄ±¡£Shuckworm¼ÌÐø¶ÔÎÚ¿ËÀ¼ÌᳫÁ˶à´Î¹¥»÷£¬×î½üµÄÄ¿±ê°üÂÞÄþ¾²²¿ÃÅ¡¢¾ü¶ÓºÍÕþ¸®×éÖ¯¡£ShuckwormʹÓõç×ÓÓʼþ×÷Ϊ³õÊ¼Ñ¬È¾ÔØÌåÀ´·Ö·¢¶ñÒâÈí¼þ£¬È»ºóʹÓÃÁËÒ»¸öеÄPowerShell½Å±¾£¬Í¨¹ýUSB·Ö·¢Æä×Ô½ç˵ºóÃŶñÒâÈí¼þPterodo¡£ÔÚ×î½üµÄ»î¶¯ÖУ¬¸ÃÍŻﻹÀûÓúϷ¨·þÎñ³äµ±C&C·þÎñÆ÷£¬°üÂÞTelegram£¬ÒÔ¼°TelegramµÄ΢²©Æ½Ì¨£¬¼´Telegraph£¬À´´æ´¢C&CµØÖ·¡£


https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/shuckworm-russia-ukraine-military


2¡¢ÃÀ¹ú·Ò×˹°²ÄÇÖݺͶíÀÕ¸ÔÖÝÊý°ÙÍò¾ÓÃñµÄÐÅϢй¶


6ÔÂ16ÈÕ±¨µÀ³Æ£¬Â·Ò×˹°²ÄÇÖݺͶíÀÕ¸ÔÖݵÄMOVEit TransferÄþ¾²Îļþ´«ÊäϵͳÔâµ½¹¥»÷£¬Êý°ÙÍò¾ÓÃñµÄÐÅϢй¶¡£Â·Ò×˹°²ÄÇÖÝ»ú¶¯³µÁ¾°ì¹«ÊÒ(OMV)͸¶£¬¿ÉÄÜËùÓÐÓµÓиÃÖÝÕþ¸®·¢±íµÄ¼ÝʻִÕÕ¡¢Éí·ÝÖ¤»òÆû³µ¹ÒºÅÖ¤µÄ¾ÓÃñ¶¼Êܵ½ÁËÓ°Ïì¡£¶íÀÕ¸ÔDMVÒ²Ðû²¼ÁËÀàËÆµÄÉùÃ÷£¬³Æ´Ë´ÎÊý¾Ýй¶Ê¼þÓ°ÏìÁËԼĪ3500000Ãû¶íÀÕ¸ÔÈË¡£¶íÀÕ¸ÔÖÝÕþ¸®ÌåÏÖ£¬ËûÃÇÎÞ·¨È·¶¨¾ßÌåµÄÊÜÓ°Ïì¸öÈË£¬Òò´Ë½¨ÒéËùÓй«Ãñ½ÓÄÉÔ¤·À´ëÊ©¡£


https://www.bleepingcomputer.com/news/security/millions-of-oregon-louisiana-state-ids-stolen-in-moveit-breach/


3¡¢»ªË¶Ðû²¼½ô¼±¹Ì¼þ¸üУ¬ÐÞ¸´Æä¶à¿î·ÓÉÆ÷ÖеÄ©¶´


ýÌå6ÔÂ19Èճƣ¬»ªË¶Ðû²¼Á˽ô¼±¹Ì¼þ¸üУ¬ÐÞ¸´Æä¶à¸ö·ÓÉÆ÷ÐͺÅÖеÄ9¸ö©¶´¡£ÆäÖаüÂÞÁ½¸öCVSSÆÀ·ÖΪ9.8µÄ©¶´£¬·Ö±ðÊÇNetatalk 3.1.12֮ǰµÄÔ½½çдÈë©¶´£¨CVE-2018-1160£©£¬¿Éµ¼ÖÂÈÎÒâ´úÂëÖ´ÐС£ÒÔ¼°Asuswrt¹Ì¼þÖеÄÄÚ´æËð»µÂ©¶´£¨CVE-2022-26376£©£¬¿ÉÄܵ¼Ö¾ܾø·þÎñ״̬»òÈÎÒâ´úÂëÖ´ÐС£¸Ã¹«Ë¾½¨ÒéÊÜÓ°Ïì·ÓÉÆ÷ÐͺŵÄÓû§¾¡¿ì½«É豸¸üе½×îй̼þ£¬²¢ÎªÎÞÏßÍøÂçºÍ·ÓÉÆ÷¹ÜÀíÒ³ÃæÉèÖõ¥¶ÀµÄÅÓ´óµÄÃÜÂë¡£


https://www.securityweek.com/asus-patches-highly-critical-wifi-router-flaws/


4¡¢FTCÖ¸¿Ø»ùÒò¼ì²â¹«Ë¾1health.ioй¶Óû§µÄ½¡¿µÐÅÏ¢


ýÌå6ÔÂ16Èճƣ¬ÃÀ¹úFTCÖ¸¿Ø»ùÒò½¡¿µ¼ì²â¹«Ë¾1health.ioδÄܱ£»¤Ãô¸ÐµÄ»ùÒòºÍ½¡¿µÐÅÏ¢¡£FTC³Æ£¬1healthÒÔǰ³ÆÎªVitagene£¬ÔÚÆäÒþ˽Õþ²ß·½ÃæÆÛÆ­Á˿ͻ§£¬×·ËÝÐԵظü¸ÄÁ˸ÃÕþ²ß£¬²¢ÔÚÆäɾ³ýÊý¾ÝµÄ¹ý³ÌÖÐÎóµ¼Á˿ͻ§¡£¸Ã¹«Ë¾±»ÒªÇóÏòFTCÖ§¸¶75000ÃÀÔªÓÃÓÚÏû·ÑÕßÍ˿²¢±»½ûÖ¹ÔÚδ»ñµÃ¿Í»§Ã÷ȷͬÒâµÄÇé¿öÏÂÓëµÚÈý·½¹²Ïí½¡¿µÊý¾Ý£¬»¹±ØÐëʵʩеÄÄþ¾²¼Æ»®¡£1healthµÄÊ×ϯִÐйٳÆFTCµÄÊÓ²ìÊÇ¡°Õþ¸®¹ý¶È¸ÉÔ¤µÄ°¸Àý¡±¡£


https://cyberscoop.com/ftc-1healthio-health-data-privacy/


5¡¢Ñо¿ÈËÔ±ÑÝʾÐÂÐͲàÐŵÀ¹¥»÷·½Ê½Freaky Leaky SMS


¾Ý6ÔÂ17ÈÕ±¨µÀ£¬Ò»×éÑо¿ÈËÔ±Éè¼ÆÁËÃûΪFreaky Leaky SMSµÄÐÂÐͲàÐŵÀ¹¥»÷·½Ê½£¬ËüÒÀÀµÓÚSMS·¢ËͳÂËßµÄʱ¼äÀ´ÍƶÏÊÕ¼þÈ˵ÄλÖ᣹¥»÷ÕßÊ×ÏÈÐèÒªÊÕ¼¯Ò»Ð©ÕÉÁ¿Êý¾Ý£¬ÒÔ±ãÔÚSMS·¢ËͳÂËߺÍÄ¿±êµÄλÖÃÖ®¼ä½¨Á¢¾ßÌåµÄ¹ØÁª¡£¹¥»÷ÕßÕÆÎÕµÄÄ¿±êÐÐ×ÙÊý¾ÝÔ½¾«È·£¬¹¥»÷½×¶ÎMLÄ£ÐÍÔ¤²âÖеÄλÖ÷ÖÀà½á¹û¾ÍԽ׼ȷ¡£´ËÍ⣬ͬһ×éÑо¿ÈËÔ±ÔÚÈ¥Ä꿪·¢ÁËÀàËÆµÄ¶¨Ê±¹¥»÷£¬¿ÉʹÓÃÏûÏ¢½ÓÊÕ³ÂËß´óÖ¶¨Î»Signal¡¢ThreemaºÍWhatsAppµÈ¼´Ê±Í¨Ñ¶¹¤¾ßµÄÓû§¡£


https://www.bleepingcomputer.com/news/security/sms-delivery-reports-can-be-used-to-infer-recipients-location/


6¡¢MandiantÅû¶UNC4841ÀûÓÃBarracuda ESG©¶´µÄ¹¥»÷ÏêÇé


MandiantÔÚ6ÔÂ15ÈÕÅû¶ÁËUNC4841ÀûÓÃBarracuda ESG©¶´µÄ¹¥»÷ÏêÇ顣ԼĪ´Ó2022Äê10ÔÂ10ÈÕ¿ªÊ¼£¬UNC4841¿ªÊ¼ÀûÓÃÔ¶³ÌÃüÁî×¢Èë©¶´£¨CVE-2023-2868£©¡£¹¥»÷ʼÓÚ°üÂÞ¶ñÒ⸽¼þµÄµç×ÓÓʼþ£¬µ±Barracuda ESGʵÑéɨÃèÎļþʱ£¬¸½¼þ»áÀûÓøÃ©¶´ÔÚÉ豸ÉÏÔ¶³ÌÖ´ÐдúÂë¡£Ò»µ©»ñÈ¡·ÃÎÊȨÏÞ£¬¾Í»áʹÓöñÒâÈí¼þϵÁÐSaltwater¡¢SeaspyºÍSeasideѬȾËü£¬À´´ÓÉ豸ÖÐÇÔÈ¡µç×ÓÓʼþÊý¾Ý¡£Mandiant»¹³ÆBarracudaÉÏÖÜÒªÇóÓû§¸ü»»É豸ÊdzöÓÚ½÷É÷µÄÄ¿µÄ£¬ÒòΪËüÎÞ·¨È·±£ÒÑÍêȫɾ³ý¶ñÒâÈí¼þ¡£


https://www.mandiant.com/resources/blog/barracuda-esg-exploited-globally